CVE-2026-67246
MEDIUMA path traversal vulnerability was found in the Wallpaper component of ADM
Title source: cnaDescription
A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit this issue to access or manipulate files outside the intended wallpaper directory, subject to user permissions and filesystem restrictions. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://www.asustor.com/security/security_advisory_detail?id=68
Scores
CVSS v4
6.9
EPSS
0.0031
EPSS Percentile
23.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
ASUSTOR Inc./ADM
4.1.0 - 4.3.3.RUN1
ASUSTOR Inc./ADM
5.0.0 - 5.1.3.RI81
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026